VulnSea

grpc vulnerabilities

CVEs whose affected-version data names the grpc package (erlang, maven, pip, rubygems). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-48853Critical
4w ago

gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

gRPC Erlang package vulnerable to Remote Code Execution with attacker-controlled gRPC payloads

Midnightgrpc · grpcEPSS 0.57%via GHSA
CVE-2026-48599High
4w ago

gRPC Erlang package's path bindings are overridable by query string and request body

gRPC Erlang package's path bindings are overridable by query string and request body

Twilightgrpc · grpcEPSS 0.27%via GHSA
CVE-2026-48854High
4w ago

gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`

gRPC Erlang package has unbounded request body accumulation in `read_full_body/3`

Twilightgrpc · grpcEPSS 0.34%via GHSA
CVE-2026-53430High
4w ago

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

gRPC Erlang package has unbounded gzip decompression (decompression bomb)

Twilightgrpc · grpcEPSS 0.35%via GHSA
CVE-2026-33186Critical· 9.1PoC
6mo ago

gRPC-Go is the Go language implementation of gRPC

gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logi…

Abyssalgrpc · grpcEPSS 1.6%via NVD
CVE-2023-4785High· 7.5
3y ago

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Denial of Service Vulnerability in gRPC TCP Server (Posix-compatible platforms)

Twilightgrpc · grpcEPSS 0.77%via OSV
CVE-2023-33953High· 7.5
3y ago

Excessive Iteration in gRPC

Excessive Iteration in gRPC

Twilightgrpcio · grpcioEPSS 0.48%via OSV
CVE-2023-32732Medium· 5.3
3y ago

gRPC connection termination issue

gRPC connection termination issue

Sunlitgrpc · io.grpc:grpc-protobufEPSS 0.53%via OSV
CVE-2023-1428High· 7.5
3y ago

gRPC Reachable Assertion issue

gRPC Reachable Assertion issue

Twilightgrpc · io.grpc:grpc-protobufEPSS 0.41%via OSV
CVE-2023-32731High· 7.4
3y ago

Connection confusion in gRPC

Connection confusion in gRPC

Twilightgrpc · io.grpc:grpc-protobufEPSS 0.50%via OSV
grpc vulnerabilities (CVEs) · VulnSea